Data Protection

How We Protect
Your Data

Because of our Edge AI architecture, we hold dramatically less data than any comparable platform. This page explains exactly what we hold, why, and how you can control it.

Shield Logo

The Edge AI Advantage

Unlike conventional safety platforms, RoseShield processes all behavioral data — browsing patterns, screen time, social signals — entirely on your device using our proprietary RoseShield Edge AI Engine.

This means raw personal data never reaches our servers. We cannot be compelled to hand over data we don't hold. We cannot be breached for data we never stored.

Raw browsing history

Never stored

Message content

Never stored

Photos or media

Never stored

Location data

Never stored

Keystroke logs

Never stored

DHSI composite score

Held (minimal)

Anonymized safety signals

Held (minimal)

Account & billing info

Held (minimal)

Data We Hold — Full Register

Every category of data we process, with purpose and retention periods

Account Data

Contains PII

Examples: Email address, name, subscription status, account preferences

Purpose: Account management, billing, service delivery

Duration of account + 90 days post-deletion

DHSI Score Data

Anonymized

Examples: Composite score (0–100), anonymized pillar scores, trend direction

Purpose: Wellbeing dashboard, school/governance reporting

24 months rolling, then permanently deleted

Safety Signal Data

Anonymized

Examples: Category flags (e.g., SCREEN_FATIGUE), delta values, confidence scores

Purpose: Safety alerts, trend analysis, policy reporting

12 months rolling

Billing Data

Contains PII

Examples: Last 4 digits of card, billing address, transaction IDs

Purpose: Payment processing via Stripe

7 years (legal requirement)

Device Identifiers

Anonymized

Examples: Anonymized device hash (not IMEI or MAC address)

Purpose: Multi-device management, license enforcement

Duration of subscription

Log Data

Anonymized

Examples: Anonymized IP prefix, browser type, app version, crash reports

Purpose: Security monitoring, debugging

90 days

Your Data Rights

Under GDPR, CCPA, and applicable privacy law, you have the following rights:

Privacy Eye Icon

Right to Access

Request a full copy of all personal data we hold about you, delivered within 30 days.

Privacy Eye Icon

Right to Rectification

Correct inaccurate or incomplete personal data. Updates take effect immediately.

Privacy Eye Icon

Right to Erasure

Request deletion of all your personal data. We complete erasure within 30 days (usually 72 hours).

Privacy Eye Icon

Right to Portability

Receive your data in a machine-readable format (JSON or CSV) for transfer to another provider.

Privacy Eye Icon

Right to Object

Object to any processing of your data not strictly necessary for service delivery.

Privacy Eye Icon

Right to Restrict

Request that we limit processing of your data while a complaint or query is being resolved.

To exercise any of these rights, email our Data Protection Officer:

We respond to all requests within 30 days. Most requests are fulfilled within 72 hours.

International Data Transfers

How we handle cross-border data flows

United States Flag

United States

Legal Basis: Standard Contractual Clauses (SCCs)

Primary Infrastructure

European Union Flag

European Union

Legal Basis: GDPR Art. 46 – SCCs

EU data residency available

United Kingdom Flag

United Kingdom

Legal Basis: UK IDTA (International Data Transfer Agreement)

UK data residency available

Australia Flag

Australia

Legal Basis: Privacy Act 1988 – APP 8

ANZ data residency available

Security Measures

  • Green CheckAES-256 encryption at rest
  • Green CheckZero-knowledge architecture for behavioral data
  • Green CheckAnnual third-party penetration testing
  • Green CheckAutomated anomaly detection on our infrastructure
  • Green CheckTLS 1.3 encryption in transit
  • Green CheckSOC 2 Type II audit (in progress)
  • Green CheckRole-based access controls (RBAC)
  • Green Check96-hour breach notification to regulators
Family Playing Soccer
DPO Checkmark Icon

Data Protection Officer

Our DPO is available for all data protection enquiries, regulatory requests, and rights exercises.

Location PinChildSafe.dev Inc. — Data Protection Officer

333 Sunset Dr, Suite 204, Fort Lauderdale, FL 33301